Available for security engagements & full-time roles

Deepak GhengatI'm a _

I break web apps, mobile apps, APIs and networks — then document exactly how to fix them.

Pune, Maharashtra, India·aka “Mr cybergod”
100+
Verified vulnerabilities
web · mobile · API · network
10+
Years hunting
researching since 2014
6
Hall of Fame programs
across public & private
100%
Report acceptance
on submitted findings
01Profile

About me

Offensive security practitioner with a decade of hands-on vulnerability research. I specialise in end-to-end assessments across web applications, mobile (Android & iOS), REST/GraphQL APIs, network infrastructure and thick-client software. I've reported 100+ verified vulnerabilities across public and private bug bounty programs, built open-source offensive tooling used by other testers, and published original research on GraphQL batching attacks.

My focus is depth over breadth on a target: I map the full attack surface, chain low-severity issues into real impact, and always ship a reproduction-ready proof of concept so engineering teams can fix fast. I work equally across web, mobile, API and network layers, and I build my own tooling when the off-the-shelf scanners fall short.

“The true value of ethical hacking lies in its ability to provide a fresh perspective and find the weaknesses that others may have missed.”

Vulnerability classes I report

Authentication BypassIDORSSRFStored & Reflected XSSSQL InjectionBusiness LogicDirectory TraversalCSRFRate-limit BypassGraphQL Batching DoSAccess ControlInfo Disclosure
Base
Pune, Maharashtra, India
Model
Remote · full-time & engagements
Focus
Web · Mobile · API · Network
Since
Researching since 2014
02Capabilities

What I test

Web Application Security

Full-scope testing of modern web apps — authentication, access control and business-logic flaws that scanners never find.

  • OWASP Top 10 & beyond
  • Authentication / session bypass
  • IDOR & broken access control
  • SSRF · XSS · CSRF
  • SQL & command injection
  • Business-logic exploitation

API & GraphQL Security

REST and GraphQL assessments including rate-limit bypass, batching abuse and authorization gaps at the API layer.

  • REST & GraphQL testing
  • GraphQL batching / DoS
  • Broken object-level auth (BOLA)
  • Mass assignment
  • Rate-limit & lockout bypass
  • Token & JWT abuse

Mobile Application Security

Android and iOS assessments covering static, dynamic and network-layer analysis of the mobile attack surface.

  • Android (APK) analysis
  • iOS (IPA) analysis
  • Static & dynamic testing
  • Insecure storage & IPC
  • ADB & runtime tooling
  • Traffic interception / SSL pinning

Network Penetration Testing

Internal and external network assessments — from discovery and enumeration to exploitation and privilege escalation.

  • External & internal pentest
  • Service enumeration
  • Vulnerability assessment
  • Exploitation & pivoting
  • Misconfiguration review
  • Network segmentation checks

Thick-Client & Systems

Desktop / thick-client application testing and OS-level security research across Windows and Linux.

  • Thick-client app testing
  • Local privilege escalation
  • Binary & config review
  • Windows / Linux internals
  • Reverse engineering basics
  • Directory traversal / LFI

Red Teaming & OSINT

Adversary-simulation mindset backed by reconnaissance and open-source intelligence to map the real attack surface.

  • Recon & asset discovery
  • OSINT gathering
  • Attack-surface mapping
  • PoC & exploit development
  • Custom Python/Bash automation
  • Responsible disclosure
03The core of my work

Bug bounty & disclosure

Continuous vulnerability research since 2014 across public and private programs. 100+ verified reports with a 100% acceptance rate, spanning web, mobile, API and network targets — and Hall of Fame recognition from multiple vendors.

Platforms:BugcrowdIntigritiHackerOneOpen Bug Bounty

Zoho

Hall of Fame

Critical & high-severity web/API findings

TripAdvisor

Hall of Fame

Authentication & business-logic flaws

Adafruit

Hall of Fame

Web application vulnerabilities

Intel

Acknowledged

Vulnerability reporting acknowledgment

Bugcrowd

Acknowledged

Verified submissions on managed programs

Intigriti

Acknowledged

European crowdsourced program findings

Recon-first
Map the full attack surface before touching a single endpoint.
Chain to impact
Turn low-severity issues into demonstrable, real-world impact.
Fix-ready reports
CVSS scoring + reproduction steps so teams remediate fast.
04Track record

Experience

Cyber Security Consultant & Security Engineer

Tigres Global

Jan 2020 — Present
Remote
  • Led penetration tests across web dashboards, REST & GraphQL APIs, auth flows and server-side infrastructure.
  • Uncovered 15+ critical and high-severity vulnerabilities and drove clean-audit remediation within 30 days.
  • Built custom Python & Bash automation for recon and exploit verification, cutting manual effort ~60%.
  • Delivered comprehensive reports with CVSS scoring and prioritised remediation guidance.

Junior Security Engineer

Lumiverse InfoSolutions

2018 — 2020
Pune, India
  • Conducted security audits and penetration tests across web applications and corporate networks.
  • Automated OWASP Top 10 detection with custom Python tooling, reducing testing time ~35%.
  • Supported secure-configuration and hardening rollouts across client infrastructure.

Independent Bug Bounty Researcher

Bugcrowd · Intigriti · HackerOne · Private Programs

2014 — Present
Remote
  • Reported 100+ verified vulnerabilities across web, mobile and API targets with a 100% acceptance rate.
  • Earned Hall of Fame recognition from Zoho, TripAdvisor, Adafruit and acknowledgment from Intel.
  • Developed reproduction-ready proof-of-concept exploits that accelerated vendor remediation.
  • Published open-source offensive tooling used by the wider testing community.
05Open source & research

Tools & research

See all repositories on GitHub
06Sharing the work

Writing & certifications

07Contact

Let's secure it.

Available for penetration testing, bug bounty engagements, security reviews and full-time roles. Email me directly and I'll get back within a day.

Email me